v7.6
Knocknoc 7.5 π6
Enhancements
KnocknocNew7.5User UI:marksAfteraloggingmajor milestone in our journey to redefine secure network access. This release is acomprehensive redesign of the user experience, delivering astreamlined, intuitive interfacethat empowers both administrators andin, end userswitharegreaternowcontrol and clarity β without compromising on power.But Knocknoc 7.5 isnβt just a faceliftβ itβs amassive uplift in features, performance, and security.β¨ New UI & Streamlined Workflow
can be organized and favorited, with recently-used entries now grouped automatically for easier return use. To ease change-control, existing installs will have this turned off by default, which can be controlled within Settings as an Admin user. This is the default for all new installs, and can be turned off in the same Admin Settings location.Redesigned interfacepresented with aresponsive,UIintuitivethatlayout- Knoc
:Cleanerimagesworkflows(newmakeusercomplexui)tasksKnocsimplerconfigurationsandcanfasterbe grouped by Administrators, with a logo added for differentiation. βLight mode: A "light mode" version now exists for Users. The default follows the system-preferences, but can be overwritten by choice the menu. A "light mode" logo can be uploaded by Administrators, until this these are provided a dark background is added to existing images.- Agent registration: Agents can be registered using a shared API key, instead of a per-agent token. This aids in IaC/CD pipeline deployments.
- Direct user assignment: Users can be directly assigned Knocs, whereas previously Groups were required.
- Knocs/Backends: Cisco Firepower added. Panos now updates "user-ID" values on Passive+ and Active settings. Simpler Panos apikey creation using Knocker.
- Audit logs: Better detail in audit-logs shown to Admin users. Improved KnocEvent detail in error cases.
Bug fixes
- Click to
revokeRevokeβ: All Knoc's/ACLs can nowavailablebealongside βclick to grantβrevoked. ImprovedServervisibilitylogs:intoServeradmin,loguserredactions were overly zealous andsystembrokeactivitycorrect log entries.- Various: Various small bug fixes, this is worth upgrading.
π Firewall & Integration EnhancementsNative orchestration for Fortinet and Palo Alto Networks(including Panorama)Unified workflow to configurePassive,Passive+, andActivemodesSimplified integration with Linux Netfilter/IPTables/IPSets (existing IPSets now visiblein your Server, per Agent)HAProxy agent capabilities are now passed to the server, including socket locations
π Credential SecurityCredentials for backend orchestrated systems(firewalls, clouds, custom scripts) are now encrypted using an approach akin to zero-knowledge, ensuring a breach of either the Server or Agent do not result in credential exposure.Custom scripts supportenvironment variables, with the username and other values passed by default (seehere)Protected (secret) environment variablesnow supported for safely passing API tokens and credentials
π SAML & Access Control ImprovementsSimpler SAML integrationand setup for administratorsUser/group mapping now supports:SAML groupsLocal groupsDynamic groups(combining local users with SAML groups)
Enhancedaccess-grant event de-duplication -boosting performance and reducing noiseIn-server SAML key management - no external handling required
βοΈ Platform and Minor EnhancementsUser license usagenow allows foroverages, preventing disruption during growth phasesIncreased logging visibility: access grants, admin actions, user activityBetter redaction in trace-level log mode to protect sensitive detailsMore ports added to discovery methods, for better CGNAT detectionCase-insensitive handling ofsessionDurationSAML variable
π Architecture SimplificationBackends and ACLs replaced with Knocsβ simplifying management
π¦ Security updates (packages)Various package updates, includingGolang security updates
Knocknoc 7.5is built for the environments where access canβt just be controlled β it needs to beearned, verified, and continuously protected. Whether you're managing critical infrastructure, complex networks, or hybrid environments, this release is designed to meet you there.It's important you update your Agents if you want to make use of the new functionality!Release Date:
10th20thAprilMay 2025